The evolution of data leak threats in a hybrid environment by 2026
Forecasts suggest that hybrid work models will encompass over 70% of global companies by 2026, fundamentally altering the cybersecurity landscape [1]. Traditional perimeter defense is inadequate as data circulates between corporate networks, cloud services, and employees' personal devices. This creates new vectors for accidental leaks and targeted exfiltration of confidential information.
The increasing use of cloud applications and remote access expands the attack surface, making data vulnerable outside a controlled environment. For Ukrainian businesses, these trends are intensified by challenges related to martial law, which may include targeted attacks on critical infrastructure and an elevated risk of insider threats.
Key data protection challenges:
- Expanding perimeter: Data is stored and processed not only on corporate servers but also in cloud storage and on personal devices.
- Rising insider threats: Unintentional employee actions or malicious insiders are significant sources of data leaks.
- Monitoring complexity: Tracking data flows in a distributed environment requires comprehensive solutions.
- Adapting to new threats: DLP systems must be continuously updated to detect new data types and exfiltration methods.
The Ukrainian context: Regulations and challenges for DLP
For Ukrainian businesses, choosing a DLP strategy is inextricably linked to national legislation and unique operational conditions. The Law of Ukraine "On Personal Data Protection" is a foundational document. By 2026, Ukraine plans to establish a new institution for personal data protection [2], indicating increased attention to this area and potential further harmonization with European standards such as GDPR, which may lead to new requirements and liabilities for violations.
Beyond legal aspects, Ukrainian companies operate under heightened risk due to ongoing hostilities. This demands particular attention to data resilience, business continuity, and protection against targeted cyberattacks. A DLP strategy must account for potential operational disruptions, the need for rapid recovery, and data protection in case of physical infrastructure loss or system compromise.
Specific considerations for Ukraine:
- Compliance with national legislation: The DLP solution must ensure adherence to the Law of Ukraine "On Personal Data Protection" and other regulatory acts.
- Protection of critical information during wartime: The necessity to protect data from physical threats, cyberattacks aimed at destabilization, and ensuring its availability under all conditions.
- Harmonization with international standards: Preparation for possible legislative changes and compliance with the requirements of international partners and investors.
- Limited resources: The need to select cost-effective solutions that provide maximum protection within available resources.
Analysis of DLP deployment models: Advantages and disadvantages for a hybrid environment
An effective DLP strategy in a hybrid environment often involves a combination of different deployment models [3]. Each has its strengths and weaknesses, as well as ideal use cases.
Network DLP
Network DLP controls data transmitted across the network perimeter by analyzing traffic. It is effective for detecting and blocking leaks that occur when data is transferred out of the corporate network.
- Pros: Centralized control, real-time leak detection, monitoring of large traffic volumes.
- Cons: Does not protect data on endpoints or in the cloud, can cause traffic delays, requires significant resources.
- Ideal scenario: Protecting the corporate perimeter, monitoring outbound traffic from on-premises servers and workstations.
Endpoint DLP
Endpoint DLP is installed directly on workstations, laptops, and servers, controlling data access, usage, and transfer. It can prevent copying to USB drives, printing, uploading to the cloud, or sending via email.
- Pros: Data protection on devices, regardless of their location, control over local data operations.
- Cons: Requires agent installation on each device, can impact performance, complexity of managing a large fleet of devices.
- Ideal scenario: Protecting data on remote workstations, laptops used outside the office, controlling local operations with confidential information.
Cloud DLP / CASB
Cloud DLP (often integrated with Cloud Access Security Broker – CASB) focuses on protecting data in cloud environments, such as SaaS applications (Microsoft 365, Google Workspace), IaaS, and PaaS. It allows controlling access to cloud resources, detecting sensitive data, and preventing its leakage through cloud channels.
- Pros: Data protection in the cloud, integration with popular cloud services, scalability, flexibility.
- Cons: Dependence on cloud service provider capabilities, potential integration issues, may not cover on-premises data.
- Ideal scenario: Protecting data in Microsoft 365, Google Workspace, Salesforce, as well as in cloud storage and applications.
Unified DLP solutions
Integrated DLP solutions combine network, endpoint, and cloud DLP functionalities into a single platform. This provides a comprehensive approach to data protection across the entire hybrid environment, simplifying management and monitoring.
- Pros: Comprehensive protection, centralized management, unified security policies, improved data flow visibility.
- Cons: Higher cost, complexity of implementation and configuration, may require significant resources.
- Ideal scenario: Large companies with complex hybrid infrastructures requiring a unified approach to data protection.
Developing an effective DLP strategy: A step-by-step guide for Ukrainian businesses
Developing a DLP strategy begins with a deep understanding of the organization’s data landscape and a clear definition of protection goals.
1. Data landscape assessment and information classification
The first step is to identify all locations where confidential information is stored (data discovery) and map its flows (data mapping). This includes both structured and unstructured data on local servers, endpoints, in cloud storage, and applications. After this, data must be classified by sensitivity level: Personally Identifiable Information (PII), Payment Card Industry (PCI) data, Intellectual Property (IP), trade secrets, etc. Clear classification allows for the application of appropriate protection policies.
2. Defining clear DLP policies
Based on data classification, DLP policies are developed that define who, how, and when confidential information can be accessed, used, and transferred. Policies must be specific, measurable, and aligned with business processes. It is important to consider Ukrainian regulatory requirements and the specifics of operating under martial law. For example, policies might prohibit uploading certain types of documents to personal cloud storage or restrict access to critical systems from unverified IP addresses.
3. Integrating DLP with other security systems
For maximum effectiveness, a DLP solution should be integrated with other components of the security system, such as SIEM (Security Information and Event Management) for centralized monitoring and event analysis, IAM (Identity and Access Management) for access control, and IRM (Information Rights Management) for data protection regardless of its location. Such integration provides a unified security picture and allows for faster incident response.
Selecting and implementing a DLP solution: Criteria and recommendations
Choosing a specific DLP solution is a strategic decision that requires careful analysis. Here are key criteria and recommendations:
Criteria for evaluating DLP solutions:
- Functionality: Capabilities for detecting, monitoring, and blocking leaks for various data types and transmission channels (network, endpoint, cloud).
- Scalability: The solution’s ability to grow with business needs and adapt to infrastructure changes.
- Integration: Compatibility with existing security systems and IT infrastructure.
- Support for the Ukrainian context: Availability of localized support, compliance with Ukrainian regulations.
- Cost: Total Cost of Ownership (TCO), including licenses, implementation, training, and support.
- Ease of management: Intuitive interface, ease of policy configuration and monitoring.
The importance of user training and fostering a security culture
Even the most sophisticated DLP system will be ineffective without proper employee training. It is crucial to conduct regular training sessions, explaining the rules for handling confidential information, the consequences of its leakage, and the principles of the DLP solution. Fostering a security culture where every employee understands their role in data protection is a critical success factor [3].
Stages of pilot implementation and effectiveness monitoring
Before full-scale implementation, it is recommended to conduct a pilot project on a limited group of users or for a specific data type. This will allow evaluating the solution’s effectiveness, identifying potential problems, and optimizing policies. After implementation, it is necessary to continuously monitor the DLP system’s operation, analyze incidents, update policies, and adapt them to new threats and changes in business processes. Regular auditing of the DLP strategy and its components is an integral part of ensuring continuous data security.
Softline IT helps plan and implement cybersecurity solutions: from current state audits to agreed-upon change plans.
Softline IT helps teams plan and implement cybersecurity, from an assessment of the current environment to an agreed change plan.
